Trojan

Should I remove “Trojan:Win32/Barys.GMA!MTB”?

Malware Removal

The Trojan:Win32/Barys.GMA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Barys.GMA!MTB virus can do?

  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Barys.GMA!MTB?


File Info:

name: 02BBF6F5DEABE7788F42.mlw
path: /opt/CAPEv2/storage/binaries/f5faeff0d9faf53e87f800d89780df6042a8bf3cc5d05923e769a836f558619b
crc32: 26376AC1
md5: 02bbf6f5deabe7788f42e27c5b9adef2
sha1: 4659ffe789801f80712b826cbc364c831e103eda
sha256: f5faeff0d9faf53e87f800d89780df6042a8bf3cc5d05923e769a836f558619b
sha512: fcd31b6a3ec0c918e9bd78bcea34d7e958db0396421e9570c1a67fd2e8b15785f79bfcd3e29521710d3f094e2b7d0722abb9b6f002775f6e22760641ecea7507
ssdeep: 3072:Kdy1eGmnIru3sIjiLb7t1XzJ2fIhdB18pl3saf17zL8hCw3BDR:yGU3BjiLb/X12AhV8pl3si/LC53BDR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11D14CF9CDDF14F93C4A831725AAB50094A34DC2A076B941AFFE7D59722EFB21644F2E0
sha3_384: c245b992b8afcccce3da73f66e6dadef31292c96731f65d0758062bcdd9112a47ce640be62c85ed5499acfc60a7ddef5
ep_bytes: c47fafe894261b6f91f722fe53b44a44
timestamp: 1976-11-05 00:00:00

Version Info:

CompanyName: Wayne J. Radburn
FileDescription: PE/COFF File Viewer
FileVersion: 0.9.9.0
InternalName: PEview
LegalCopyright: Copyright© 1997-2011 Wayne J. Radburn
OriginalFilename: PEview.exe
ProductName: PEview
ProductVersion: 0.9.9.0
Translation: 0x0409 0x04e4

Trojan:Win32/Barys.GMA!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebTrojan.PackedENT.192
MicroWorld-eScanGen:Variant.Lazy.432776
SkyhighBehavesLike.Win32.Sytro.cc
ALYacGen:Variant.Lazy.432776
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0001b3411 )
K7GWTrojan ( 00571f921 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.36608.l80@aS09i7l
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.HHBK
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Packed.Dridex-9861223-1
KasperskyVHO:Trojan.Win32.Copak.gen
BitDefenderGen:Variant.Lazy.432776
NANO-AntivirusTrojan.Win32.Kryptik.foobtk
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Kryptik.gify
EmsisoftGen:Variant.Lazy.432776 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
VIPREGen:Variant.Lazy.432776
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.02bbf6f5deabe778
SophosMal/Inject-GJ
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Lazy.432776
JiangminTrojan.Generic.cuiil
WebrootW32.Trojan.Gen
VaristW32/Dacic.E.gen!Eldorado
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=81)
Antiy-AVLGrayWare/Win32.Kryptik.gifq
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Kryptik.TLS@812zm8
ArcabitTrojan.Lazy.D69A88
ZoneAlarmVHO:Trojan.Win32.Copak.gen
MicrosoftTrojan:Win32/Barys.GMA!MTB
GoogleDetected
AhnLab-V3Packed/Win.FJB.R621354
McAfeeTrojan-FVOQ!02BBF6F5DEAB
TACHYONTrojan/W32.Selfmod
VBA32Trojan.Khalesi
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.B34D (CLASSIC)
IkarusTrojan.Patched
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.GIFQ!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.789801
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Barys.GMA!MTB?

Trojan:Win32/Barys.GMA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment